We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 99e8cb7 commit 078d3d0Copy full SHA for 078d3d0
python/ql/test/query-tests/Security/CWE-209-StackTraceExposure/test.py
@@ -1,4 +1,4 @@
1
-from flask import Flask, request, make_response
+from flask import Flask, request, make_response, jsonify
2
app = Flask(__name__)
3
4
@@ -56,3 +56,15 @@ def format_error(msg):
56
@app.route('/maybe_xss')
57
def maybe_xss():
58
return make_response(request.args.get('name', ''))
59
+
60
+# BAD
61
+@app.route('/bad/jsonify')
62
+def bad_jsonify():
63
+ try:
64
+ do_computation()
65
+ except Exception as e:
66
+ return jsonify({"error": str(e)})
67
68
69
+if __name__ == "__main__":
70
+ app.run(debug=True)
0 commit comments